← Back to home

Security at Semantiks

1. Compliance programme and independent assurance

2. Where Customer Data is stored and processed

Customer Data is stored and processed in the United States. Semantiks runs on Google Cloud Platform and Amazon Web Services:

Personnel access. Semantiks personnel who access production systems are engaged directly by Semantiks Inc. under United States contracts and are bound by the confidentiality and access controls described below. No Customer Data is stored outside the United States.

3. Encryption

4. Artificial-intelligence model providers

OpenAI is the sole model provider used in production. No other model provider receives Customer Data. Semantiks operates under an OpenAI Enterprise Agreement, executed July 1, 2026, which contractually prohibits the use of Customer Data to train generalized models. Semantiks likewise does not use Customer Data to train generalized models.

Customer conversations, including transcriptions of end-user voice messages, are processed by OpenAI to generate agent responses. Media that end users send in a conversation — images, documents, and voice messages — is stored in Semantiks-controlled storage in the United States.

5. Access to production systems

6. Secure development

7. Human oversight of agent decisions

Semantiks agents operate under human supervision rather than in isolation. Customers have:

8. Subprocessors

Semantiks maintains a current register of subprocessors that may process Customer Data, identifying each provider, its purpose, and its hosting location. The register is provided to customers and prospective customers under a non-disclosure agreement on request, rather than published, and forms part of the Data Processing Addendum.

9. Retention and deletion

Customers may request export or deletion of Customer Data, including during the term and on termination. Deletion requests are executed by the Semantiks engineering team; automated, customer-initiated deletion is in development. Retention periods, the post-termination export window, and residual backup copies are described in the Privacy Notice, and contractual deletion timelines are set in the Data Processing Addendum.

10. Security incidents

Semantiks notifies affected customers of a confirmed security incident affecting their Customer Data without undue delay, and provides the information reasonably available to support the customer’s own legal obligations. Specific notification windows are committed contractually in the Data Processing Addendum. Semantiks has experienced no security incidents to date.

11. Availability

Semantiks does not publish an uptime figure at this time, and will not quote one until it is backed by measurement. A public status page is in progress. Availability commitments, where offered, are set in the applicable customer agreement.

12. Reporting a security issue

Report suspected vulnerabilities or security concerns to [email protected]. We acknowledge reports and will work with you on validation and remediation. We do not pursue legal action against researchers who report in good faith, avoid privacy violations and service degradation, and give us reasonable time to remediate before disclosure.

13. Related documents